IRAP PROTECTED-level collaboration platforms: A guide for government leaders
IRAP certification proves a platform meets ASD security rules for PROTECTED data. See how top collaboration platforms compare.
IRAP certification proves a platform meets ASD security rules for PROTECTED data. See how top collaboration platforms compare.
An IRAP PROTECTED-level collaboration platform is a secure cloud solution that has been independently assessed to meet strict regulations set by the Australian Cyber Security Centre (ACSC). These rules ensure that the solution can safely process, store, and transmit sensitive, high-value government data.
With the rapid increase in frequency and sophistication of potential cyberattacks, it’s hardly surprising that public sector entities are keen to make the switch. According to a recent report, 32% of breaches involved data stored across multiple environments, including public cloud, private cloud, and on-premises infrastructure, emphasising the need for a single, standardised solution.
According to our most recent Connected Government Report , 55% of IT leaders say vulnerable legacy systems are a major concern. That number drops to 33% across all other sectors.
The need for enterprise-grade, IRAP PROTECTED-level collaboration platforms is clear. Knowing whether a platform is capable of delivering these vital security objectives may be less so.
That’s where this article can help. We’ll explore the critical tension between fulfilling modern productivity demands and adhering to strict data sovereignty obligations. Then we’ll take a close look at the platforms that have achieved PROTECTED-level status.
We’ll also examine the core technical requirements that a robust PROTECTED-level collaboration platform should feature before touching on how agentic AI can augment critical security environments for many years to come.
At the centre of the Australian public sector cloud procurement sits the Information Security Registration Assessors Program (IRAP). For government IT leaders, navigating cloud compliance is often a tricky endeavour with many competing facets. What this certification actually is and what it means is often misinterpreted to some extent.
The most critical distinction to make is that IRAP is an assessment process rather than a static pass or fail designation.
The Australian Signals Directorate (ASD) governs a framework of highly-trained, independent IRAP assessors who will examine a vendor’s system architecture, operational processes, data protection scope, and physical security against controls dictated by the Information Security Manual (ISM). These parameters are malleable, and they can change with the introduction of new third-party integrations or AI features. In other words, a compliant status isn’t permanent.
It’s also important to understand that IRAP status isn’t a fixed, blanket designation across all cloud configurations and functions. A platform may be IRAP-assessed for protected data when deployed in a sovereign cloud environment, but it may be completely unassessed when deployed as, for example, a standard public SaaS model.
So when it comes to procurement and evaluating potential collaboration tools, your procurement team must get the full IRAP Assessment Report to find out exactly which features and deployment models were evaluated. That’s the only way to confirm that they match your organisation’s needs.
For the purposes of this article, we’re evaluating the need for governmental and public IT departments to deploy collaboration platforms that are capable of managing PROTECTED data. OFFICIAL: Sensitive is another classification that’s often used interchangeably, but there are clear distinctions between the two.
| Criteria | OFFICIAL: Sensitive | PROTECTED |
|---|---|---|
| Data type and impact | Routine business operations, internal communications, limited distribution of unclassified data | Highly sensitive data, where a compromise would cause serious damage to national security |
| Compliance expectation | Standard, robust commercial security practices | Strict adherence to expanded ISM controls |
| Data at rest (storage) | Can be stored in standard public, multi-tenant cloud environments with industry-standard encryption | Requires highly isolated storage environments with end-to-end encryption generated and held exclusively by the agency |
| Data in transit (transmission) | Standard commercial encryption, such as standard TLS | Must occur over highly secure networks |
| Sovereignty | Data and metadata can reside in offshore data centres | Data and metadata must remain wholly within Australia |
While both tiers require a comprehensive access level, the baseline technical safeguards for data storage and transmission diverge sharply once you cross the threshold into PROTECTED workloads.
To ensure you’re getting a collaboration platform that’s capable of handling PROTECTED-level workloads for governmental and public IT departments, you must evaluate platforms with a strict technical lens. Data isolation, cryptographic sovereignty, and operational transparency must be at the core of the architecture.
Let’s explore the critical technical capabilities and features that your prospective vendor should be able to demonstrate in their platform.
Your security team will need to make sure that the platform mandates ASD-Approved Cryptographic Protocols (AACP) for all data in transit. For data at rest, look for platforms that support Bring Your Own Key (BYOK) options. If the vendor retains control of the master encryption keys, then your agency or organisation won’t truly have data sovereignty.
In standard multi-tenant public cloud architectures, a single software bug or configuration error has the potential to undermine the security of all organisations contained within the platform. For PROTECTED-level data, look for platforms engineered with strict logical isolation capabilities, such as a dedicated virtual network.
You can also check for deployment options within physically isolated sovereign cloud zones, but this can cast doubt on true data sovereignty.
Your chosen platform should provide tamper-evident, centralised logging of all user activities, administrative changes, and file access events to satisfy the strict auditing requirements of the ISM. These logs must be easily ingested into your agency’s central security event management system for real-time monitoring.
A reputable vendor will go out of its way to provide comprehensive documentation and explicit transparency. Look for platforms that offer line-by-line mapping of software features against hundreds of applicable controls in the ASD’s Information Security Manual.
They’ll also identify precisely where their security obligations end and where your agency’s configuration responsibilities begin.
Always keep in mind that a vendor’s IRAP Assessment Report only proves that their underlying platform is capable of meeting ISM controls. It doesn’t automatically mean that your specific architecture is secure. It’s your security team’s responsibility to ensure that the platform is utilised to its full potential.
Collaboration platforms are highly interactive and dynamic. They often rely on connected systems that share and update information regularly across organisational boundaries. That can make it hard to keep track of.
Your IT team will need to be aware of a few collaboration-specific features and associated rules, including:
Modernise government service and increase operational efficiency with proactive agents and automation. Use Salesforce software for government to unify and harmonise data on a compliance-enabled cloud. Innovate faster with a low code application platform for government.
Most organisations use multiple tools to handle different tasks. IT teams need to confirm that each vendor’s IRAP status meets their organisation’s security requirements and that the software works with their existing systems. What works for one agency might not be the ideal solution for another.
Let’s look at how the leading enterprise platforms meet the technical requirements for government agencies.
| Platform | Local IRAP status | Primary data residency | Identity and access strengths | Integration depth and footprint |
|---|---|---|---|---|
| Salesforce + Slack | PROTECTED, assessed on local Hyperforce architecture | 100% onshore via Australian Hyperforce zones | Robust conditional access, granular session controls, full Salesforce Shield key governance | Deep structural integration, combining conversational chat natively with enterprise core records and AI agents |
| Microsoft 365 + Teams | PROTECTED, assessed across core enterprise suites | Onshore across dedicated Australian data centres | Industry-standard via Azure AD/Entra ID | Exceptional native document co-authoring and telephony integration |
| Google Workspace | OFFICIAL: sensitive; individual agencies pursue custom PROTECTED plans | Selected storage locales can be pinned onshore | Strong cloud-native identity baselines, hardware security key support | Lightweight, browser-first collaboration, though deep legacy enterprise systems require extensive middleware |
| Atlassian Cloud | IRAP-assessed; specific tiers support PROTECTED status | Local data residency controls are available for primary data objects | Centralised via Atlassian Access, supporting standard SAML single sign-on | Potential leader for technical project tracking, agile development pipelines, and DevOps workflows |
| Cisco Webex | PROTECTED, assessed via specialised architectures | Onshore media and data processing elements are pinned locally | Enterprise-grade identity management with strict end-to-end cryptographic boundaries | Built intentionally for hardware-heavy conference spaces and high-fidelity video streams |
There’s one important thing to keep in mind when selecting a platform: No single platform will satisfy every one of your ISM compliance requirements. You’ll likely need to use multiple systems to ensure you meet PROTECTED criteria.
Historically, team chat platforms and enterprise case files lived in entirely different silos and created both operational and compliance issues. With Salesforce + Slack, collaboration isn’t separate from the work; it’s integrated.
By utilising Hyperforce, agencies can run their entire customer relationship management (CRM), Data Cloud, and Slack workspaces within an environment that successfully cleared its independent IRAP PROTECTED assessment in 2025.
These systems are designed to work together, which means Agentforce 360 can safely bring AI agents into the PROTECTED government environment. The AI follows strict security rules, manages complex tasks, and sends the results through secure Slack channels. That’s where humans then make the final decisions.
Transitioning to an IRAP PROTECTED collaboration environment is a major security decision that government IT leaders need to evaluate carefully. To make that transition easier for everyone, procurement and IT teams need to choose a solution that meets security requirements and works well for daily operations.
These questions will help you balance the two:
Verify which modules, data centres, and feature sets have been evaluated. Not all assets and functions within a platform are scrutinised to the same degree, so it’s essential to confirm that the components you’ll be using have been assessed.
Your agency must retain exclusive control over the generation and lifecycle of encryption keys safeguarding data at rest in order to maintain true data sovereignty.
Under the ISM, backend infrastructure engineers or support staff who can view active system logs or support tickets must be located onshore and hold appropriate Australian security clearances.
An organisation, not the platform, is responsible for meeting the Essential Eight requirements. But the platform needs to provide the features that will help the organisation do that, such as support for patching, MFA, and privilege restriction policies.
Recent federal performance benchmarks reveal a striking paradox within public sector cybersecurity. Agencies are, for the most part, heavily invested in data governance, but they appear to be struggling with technical execution.
This is supported by findings from the ASD’s 2025 Commonwealth Cybersecurity Posture report , which found that only 22% of entities achieved Maturity Level 2 across all areas of the Essential Eight framework, despite more than 90% maintaining formal incident response plans.
Image source: Gadget Access
The numbers suggest that while organisations are committed to increasing cybersecurity, many IT departments may not have the skills or resources available to configure, secure, and regularly review a PROTECTED-level cloud environment.
This technical strain is further complicated by severe data fragmentation across government networks, with a recent survey indicating that disconnected databases are making work harder for 72% of Australian public sector workers. Data silos limit the value that advanced software is designed to deliver.
The consequences of a fragmented system are often costly and dangerous data breaches. As part of its Cost of Data Breach Report (2025) , IBM found that the average cyber breach cost is around AUD$4.26 million, a 27% increase since 2020.
It makes budgeting for the total cost of compliance all the more critical. Investing in a properly assessed, secure collaboration system mitigates both financial liability and operational fragmentation, allowing teams to break down silos safely.
As government sector IT teams look to incorporate artificial intelligence (AI) safely into their infrastructure, they face a major obstacle. Traditional generative AI models are largely built on public cloud environments where data exposure risks and a lack of auditability are common.
Until recently, autonomous agents weren’t considered a viable option for organisations that must comply with ISM. Now there are platforms, like Agentforce, that have cleared independent IRAP assessments up to the PROTECTED data tier.
This means that an AI agent isn’t a separate, unvetted entity operating outside a security perimeter anymore. Instead, it functions directly inside your compliant, onshore infrastructure. It retains its core collaborative functionality, whether that’s to manage complaints or accelerate response times for public enquiries, while maintaining a permanent record of interactions for future review.
The collaboration architecture an agency chooses today will affect its effectiveness for the next ten years. Organisations that choose a cloud platform based on convenience rather than a careful evaluation risk being stuck with systems that can’t adapt to changes or meet PROTECTED level compliance requirements.
By prioritising deep data integration, strict onshore data residency, and native, IRAP-assessed AI layers, government IT leaders can build agile digital workspaces that balance the necessity of data sovereignty with the transformative power of modern collaboration.
Ready to modernise your agency’s collaboration infrastructure safely? Contact the Salesforce Public Sector team today to review our detailed cloud control protocols and learn how to fast-track your agency’s path to PROTECTED-level Authority to Operate.
Activate Data 360 for your team today.
An IRAP-assessed collaboration platform is a digital communication and workplace solution that has been evaluated by a certified, independent third-party auditor using the Information Security Registered Assessors Program (IRAP) framework. This process determines whether the platform satisfies the compliance requirements of the Australian Signals Directorate’s (ASD) Information Security Manual (ISM) controls.
No. An IRAP assessment is simply an independent point-in-time audit report outlining a platform’s security capabilities. It doesn’t translate into an automatic, permanent pass or fail or a stamp of approval from the government.
No, it isn’t. While storing core database files is mandatory, the ISM also dictates that all forms of metadata, data processing, and operational personnel are native as well. Any form of offshore functionality within a data lifecycle could be enough to jeopardise PROTECTED-level compliance.
No. An IRAP assessment only covers the specific software modules and deployment models explicitly defined in the assessment’s scope document. If your cloud security team installs third-party apps or marketplace plugins, they’re excluded from the core vendor’s assessment and could make your entire operation non-compliant.